Technical information
- Android.Backdoor.481.origin
- UDP(DNS) <Google DNS>
- TCP(HTTP/1.1) b.nin####.cn:80
- TCP(HTTP/1.1) 1####.171.131.72:80
- TCP(HTTP/1.1) 1####.171.131.73:80
- TCP(HTTP/1.1) w####.pcon####.com.cn:80
- TCP(HTTP/1.1) cg.m####.com:80
- TCP(HTTP/1.1) img.nin####.cn:80
- TCP(HTTP/1.1) s.nin####.cn:80
- a####.x####.co
- a####.x####.com
- b.nin####.cn
- c.nin####.cn
- cg.0####.com
- cg.m####.com
- icg.1####.com
- icp.1####.com
- img.nin####.cn
- mt####.go####.com
- oc.x####.co
- oc.x####.com
- s.nin####.cn
- w####.pcon####.com.cn
- img.nin####.cn/dat/b/1.0.5/12.dat
- img.nin####.cn/dat/p/2.1.6/12.dat
- b.nin####.cn/admin/scs.action?requestId=####
- cg.m####.com/pop/gc
- cg.m####.com/pop/gd
- cg.m####.com/pop/up
- s.nin####.cn/admin/sc.action?requestId=####
- w####.pcon####.com.cn/ip.jsp?qq-pf-to=####
- /data/data/####/.lock
- /data/data/####/1.jar
- /data/data/####/13.jar
- /data/data/####/14.jar
- /data/data/####/15.jar
- /data/data/####/2.jar
- /data/data/####/39724f0b-b2a6-4c1c-86ba-9ac37d71bdba
- /data/data/####/9j_recommend.xml
- /data/data/####/box_cp_states.xml
- /data/data/####/boxcpdownloads
- /data/data/####/boxcpdownloads-journal
- /data/data/####/c
- /data/data/####/c.jar
- /data/data/####/cachetimesha_sidebar.xml
- /data/data/####/com.jsrcvhazxmichalfre.friutsbreak_preferences.xml
- /data/data/####/daemon
- /data/data/####/dim.xml
- /data/data/####/dls-journal
- /data/data/####/eca.db-journal
- /data/data/####/eck.xml
- /data/data/####/fb496951-6866-4dba-b89b-9c2d944be6c3
- /data/data/####/ic.jar
- /data/data/####/iceca.db-journal
- /data/data/####/icecd.db-journal
- /data/data/####/icpk.xml
- /data/data/####/mid.xml
- /data/data/####/mobclick_agent_cached_com.jsrcvhazxmichalfre.friutsbreak
- /data/data/####/mobclick_agent_header_com.jsrcvhazxmichalfre.fr...ak.xml
- /data/data/####/mobclick_agent_state_com.jsrcvhazxmichalfre.fri...ak.xml
- /data/data/####/running_app_name.xml
- /data/data/####/t
- /data/data/####/type.xml
- /data/data/####/xy.xml
- /data/media/####/1.dat
- /data/media/####/MID.DAT
- /data/media/####/d.dat
- /data/media/####/names.dat
- /data/media/####/packgename.txt
- /data/media/####/share.dat
- chmod 777 <Package Folder>/daemon
- sh
- 39724f0b-b2a6-4c1c-86ba-9ac37d71bdba
- fb496951-6866-4dba-b89b-9c2d944be6c3
- wiengine
- wiengine_binding
- wisound
- DES
- DES-CBC-PKCS5Padding
- DES
- DES-CBC-PKCS5Padding